Skip to content

History / Security Configuration

Revisions

  • docs: v1.13.0 withdrawn; version notes name v1.13.1

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: sign-in usernames in v1.13.1; version notes now name v1.13.0

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: security hardening, sealed instance sync and key pinning (#296) - new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS, TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES syncKeyId/syncPublicKey; compose pass-through note - secret rotation, admin env credentials, password policy, sessions - forward auth ports, portal rate limits, header stripping - instance sync sealing, key pinning, instance editing, CA keys - WAF directive rules, redaction, quick templates; placeholders - REST endpoints, troubleshooting entries, upgrade checklist - documentation IP ranges in Geo Blocking examples Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b

    @fuomag9 fuomag9 committed Sep 26, 2026
  • Fix broken TOC anchors and duplicate Excluded Paths section Correct TOC entries pointing at renamed/missing headings across several pages, add sections that were missing from their TOCs, and merge the two conflicting Excluded Paths sections in the Forward Auth guide into one accurate description (protected-paths precedence, glob wildcard matching). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9

    @fuomag9 fuomag9 committed Jul 23, 2026
  • Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths - Add DNS-Provider-Configuration page covering all 12 supported DNS providers - Replace Cloudflare-only DNS page with redirect to new multi-provider page - Update all cross-references from Cloudflare DNS to DNS Provider Configuration - Add excluded paths section to Forward Auth guide - Fix Contributing page: NextAuth.js → Better Auth in tech stack - Add dns-providers and oauth-providers to REST API endpoint table - Fix outdated OAuth callback URL format in Troubleshooting - Update Environment Variables: Cloudflare settings → DNS Provider settings Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @fuomag9 fuomag9 committed Apr 18, 2026
  • Update docs for 1.0-RC: Better Auth migration, new OAuth callback URLs - OAuth callback URL changed from /api/auth/callback/oauth2 to /api/auth/oauth2/callback/{provider-id} - Document UI-based OAuth provider management (Settings → OAuth Providers) - Update rate limiting docs: Better Auth built-in (AUTH_RATE_LIMIT_*) replaces legacy LOGIN_* vars for auth endpoints - Add AUTH_TRUST_HOST env var documentation - Update account unlinking docs (now supported via Profile page) - Add upgrade notice for users migrating from < 1.0-RC Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @fuomag9 fuomag9 committed Apr 12, 2026
  • Add wiki pages for forward auth, user management, and mTLS RBAC New pages: - Feature-Guide-Forward-Auth.md — built-in IdP, groups, per-host access - Feature-Guide-User-Management.md — roles, admin page, groups, OAuth users - Feature-Guide-mTLS-RBAC.md — roles, cert trust, path-based access rules Updated pages: - Home.md — add links to new feature guides - Feature-Guide-Proxy-Hosts.md — add forward auth, location rules, mTLS RBAC - Security-Configuration.md — add user roles section - OAuth-Authentication-Setup.md — add forward auth integration section Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @fuomag9 fuomag9 committed Apr 6, 2026
  • update wiki

    @fuomag9 fuomag9 committed Mar 12, 2026
  • made test credentials more coherent

    @fuomag9 fuomag9 committed Jan 30, 2026
  • added docs

    @fuomag9 fuomag9 committed Dec 29, 2025